Minnesota Water Attacks and the Predictable Reality
How possible Iran-linked actors exploited exposed PLCs in the 2026 Minnesota water attacks. MITRE ATT&CK mapping, risk matrix, and OT security lessons from Lares.
A real-world test of your security controls, policy, technology, and infrastructure effectiveness.

The term originated within the military to describe a team whose purpose is to penetrate the security of "friendly" installations and thus test their security measures.
In this style of testing, the Lares engineering team test many types of attacks through a comprehensive combination of Physical, Social, and Electronic techniques.
We utilize a custom-designed approach that analyzes multiple attack vectors across various levels of business and personal landscapes. This combined analysis delivers a unique view of the blended threats an organization must be adequately prepared to protect against.
Our engineers attempt to gain physical access to employee-only areas, network closets, and data centers. We also test your human perimeter by engaging employees via phone or in person with dynamic pretexts or visually deceptive emails.
We perform a proactive, authorized attempt to compromise information security and access sensitive data by exploiting vulnerabilities. This includes exploiting locally installed software to assess an organization's patch management presence and diligence.
At the end of a Lares Red Team engagement, a detailed debrief session with management and key stakeholders is always held. This ensures we thoroughly address any questions, comments, or concerns regarding the exercise and its results.
We begin by acting as an unauthenticated external adversary, analyzing your organization's digital footprint. The Lares Intelligence Gathering methodology uses a custom-designed approach to map multiple attack vectors across business and personal landscapes, identifying exposures before a single packet is sent.
Key Activities: Phone conversations (vishing), electronic solicitation (phishing), and onsite physical security testing.
Moving beyond scanning, we perform a proactive, authorized attempt to compromise information security by exploiting discovered vulnerabilities. We simulate advanced threat actors to bypass external defenses, exploit locally installed software, and evaluate your organization’s patch management and defensive diligence.
Key Activities: Wireless testing, network penetration, and targeted application exploitation.
Moving beyond scanning, we perform a proactive, authorized attempt to compromise information security by exploiting discovered vulnerabilities. We simulate advanced threat actors to bypass external defenses, exploit locally installed software, and evaluate your organization’s patch management and defensive diligence.
Key Activities: Wireless testing, network penetration, and targeted application exploitation.
Once initial access is achieved, we pivot our focus to lateral movement and privilege escalation. We test how far an attacker can go, evaluating your internal detection capabilities and verifying whether critical data can be accessed, manipulated, or simulated for exfiltration without triggering your security operations center (SOC).
Key Activities: Lateral movement, credential harvesting, and simulating data exfiltration.
A Red Team exercise is only as valuable as the improvements it drives. At the end of every engagement, Lares provides a detailed debrief session with management and key stakeholders. We deliver prioritized remediation guidance tailored for executives, along with actionable, technical fixes for your engineering teams.
Key Activities: Executive summaries, detailed technical findings, and collaborative playbook refinement.
A penetration test focuses on identifying as many vulnerabilities as possible within a strictly defined scope (such as a specific application or network segment) over a short period. A Red Team assessment is objective-based and much broader. It simulates a real-world adversary using "low and slow" techniques to test your organization's entire defensive posture—evaluating how well your people, processes, and technology detect and respond to an active, targeted attack.
No. Lares adversarial engineers operate under strict rules of engagement designed to emulate sophisticated threats without causing operational downtime, system instability, or data destruction. Throughout the exercise, we maintain continuous, out-of-band communication with a designated internal "White Cell" (a trusted point of contact) to ensure the engagement remains safe and controlled at all times.
Yes. Modern threat actors don't restrict themselves to just a keyboard, and neither do we. Depending on your organization's specific goals, our blended-threat approach can include attempting to bypass physical facility controls (tailgating, lock bypassing) and utilizing social engineering (phishing, vishing) to test your human perimeter alongside electronic defenses.
Because we emulate Advanced Persistent Threats (APTs) that actively try to avoid detection by your Security Operations Center (SOC), Red Team engagements are naturally longer than standard penetration tests. A typical engagement spans several weeks to a few months, allowing our engineers to conduct thorough reconnaissance, develop custom pretexts, and execute lateral movement carefully.
You will receive more than just a list of vulnerabilities. We deliver a comprehensive report that includes an executive summary, a detailed attack narrative mapping our actions to the MITRE ATT&CK framework, and a timeline of events to compare against your internal SOC logs. Finally, we provide actionable, role-based remediation guidance tailored for both leadership and your engineering teams, followed by a thorough stakeholder debriefing.




